
| ´Ù¸¥À̸§ | |||
|---|---|---|---|
| ´ëÇ¥Àû Áõ»ó | ºÐ¼® ³»¿ë ÂüÁ¶ | ||
| ¹ß°ßÀÏ | ±¹³» : 2010-02-24 ÇØ¿Ü : 2010-02-24 | ||
| ºÐ·ù | Worm | Ȱµ¿ ¹üÀ§ | À©32 |
| ÆÄ±«µµ/È®»êµµ | / ![]() |
ƯÁ¤ Ȱµ¿ÀÏ | -- |
| Á¦ÀÛ±¹°¡ | ºÒºÐ¸í | ¾ÏÈ£È ¿©ºÎ | ºñ¾ÏÈ£È |
| °¨¿°À§Ä¡ | ¾øÀ½ | ½Ã½ºÅÛ ¸Þ¸ð¸® »óÁÖ¿©ºÎ |
ºñ»óÁÖ |
| ¹ÙÀ̷κ¿ ´ëÀÀÁ¤º¸ |
2010-02-24 [Áø´ÜÄ¡·á°¡´É]
|
||
1) ¾Ç¼ºÄڵ尡 ½ÇÇàµÇ¸é ´ÙÀ½°ú °°Àº °æ·Î¿¡ ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. (·çÆ®Æú´õ)\RECYCLER\(SID)\Desktop.ini (·çÆ®Æú´õ)\RECYCLER\(SID)\windll.exe 2) ·¹Áö½ºÆ®¸®¸¦ Ãß°¡ÇÏ¿© ºÎÆÃ½Ã ½ÇÇàµÈ´Ù. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon - Taskman : (·çÆ®Æú´õ)\RECYCLER\(SID)\windll.exe 3) »ý¼ºµÈ windll.exe Àº explorer.exe ¿¡ ÇÚµé·Î ÀÎÁ§¼Ç µÇ¾î µ¿ÀÛÇϸç, ƯÁ¤ ¼¹ö¿¡ Á¢¼ÓÀ» ½ÃµµÇÏÁö¸¸ ÇöÀç Á¢¼ÓµÇÁö ¾Ê´Â´Ù. sxvx.xo-xp.xix (6x.2x0.x7x.1x4) sxvxb.xexmxix.cxm (6x.2x0.x7x.1x9) bxoxtxr.xsxr.xs (x7.x1x.x7x.x3x) |
|||
|
|
|||
|
|
|||
|
1. WinXP / ME »ç¿ëÀÚ¶ó¸é ½Ã½ºÅÛ º¹¿ø ±â´ÉÀ» ºñȰ¼ºÈ ÇÑ´Ù. a. ½Ã½ºÅÛ º¹¿ø ºñȰ¼ºÈ ¹æ¹ý (WInXP) b. ½Ã½ºÅÛ º¹¿ø ºñȰ¼ºÈ ¹æ¹ý (WinME) ½Ã½ºÅÛ º¹¿ø ±â´ÉÀ» ºñȰ¼ºÈ ÇÏ´Â ÀÌÀ¯´Â ±ú²ýÇÏ°Ô ¹ÙÀÌ·¯½º¸¦ Ä¡·áÇϱâ À§ÇؼÀÌ´Ù. °ü·Ã Á¤º¸´Â MS ȨÆäÀÌÁö ±â¼ú¹®¼(Q263455) ¿¡¼ È®ÀÎ ÇÒ ¼ö ÀÖ´Ù. 2. ¹é½Å ¿£ÁøÀ» ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ® ÇÑ´Ù. ÀÌ ¹ÙÀÌ·¯½º¸¦ Ä¡·áÇϱâ À§Çؼ´Â ÃÖ½ÅÀÇ ¹é½Å ¿£ÁøÀÌ ÇÊ¿äÇÏ´Ù. a. ¹ÙÀ̷κ¿ Á¤½Ä »ç¿ëÀÚÀÇ °æ¿ì : - Á¦Ç°±ºÀ» ÅëÇØ ¾÷µ¥ÀÌÆ® b. ¹ÙÀ̷κ¿À» »ç¿ëÇÏÁö ¾Ê´Â ÀÏ¹Ý °í°´ - ¶óÀ̺êÄÝ(¹«·á°Ë»ç) »çÀÌÆ®¸¦ ÀÌ¿ëÇÑ ¹ÙÀÌ·¯½º °Ë»ç - ¹ÙÀ̷κ¿ 7ÀÏ Æò°¡ÆÇ ¼³Ä¡ ÈÄ ¹ÙÀÌ·¯½º °Ë»ç 3. ½ºÆÄÀÌ¿þ¾î °Ë»ç¸¦ ÇÑ´Ù. a. ¹ÙÀ̷κ¿À» ½ÇÇàÇÏ¿©, ȯ°æ ¼³Á¤¿¡¼ ½ºÆÄÀÌ / ¾Öµå¿þ¾î °Ë»ç¸¦ ÇÑ´Ù. - Desktop 5.X : [µµ±¸]-[ȯ°æ¼³Á¤]-[½ºÆÄÀÌ¿þ¾î °Ë»ç] ¸ðµç ÆÄÀÏ Ã¼Å© - ¶óÀ̺êÄÝ(¹«·á°Ë»ç) : [°í±Þ°Ë»ç] üũ b. ¹ß°ßµÇ´Â ¸ðµç ½ºÆÄÀÌ¿þ¾î¿¡ ´ëÇØ¼ Ä¡·áÇÑ´Ù. c. [ÀçºÎÆÃ ÈÄ ÀÚµ¿ Ä¡·á] ¸Þ½ÃÁö°¡ ³ªÅ¸³µ´Ù¸é ÀçºÎÆÃÀ» ÇÑ ÈÄ¿¡ ´Ù½Ã °Ë»çÇÑ´Ù. |

